Remaining Driven in Face of Obstacles

Angela Thomas, MS-MIS, MBA, audit coordinator for DFA Office of Internal Audit, recently passed the Certified Information Systems Auditor (CISA) exam. Here, she shares her story on how not giving up led her to success.

I took the CISA Exam for the first time in December 2014. My preparation for the December 2014 exam included reading and studying the following material:

  • ISACA’s 2014 CISA Supplemental Manual containing 100 sample questions
  • IT Auditing Using Controls to Protect Information Assets, 2nd Edition, by Chris Davis
  • CISA Certified Information Systems Auditor Study Guide, by David L. Cannon
  • CISA Certified Information Systems Auditor All-in-One Exam Guide, 2nd Edition, by Peter Gregory

I did not pass the December 2014 exam—I was disappointed about that, but I did not give up! I dusted off the above study materials, began studying again and registered for the June 2015 exam.  In addition to the above study materials, I purchased ISACA’s 2015 CISA Review Manual (CRM) that contains 1,100 sample questions, joined ISACA’s CISA Study Community Discussion and joined ISACA’s Official LinkedIn Group.

I obtained many online resources via the CISA Study Community that helped enhance my knowledge and understanding. I also gained some resources from the LinkedIn Group. I read the ISACA 2015 CISA Review Manual three times. The first time I read each question slowly and thoroughly and studied why each correct answer was the correct answer and why each incorrect answer was the incorrect answer. My second and third readings consisted of reading each question to try and select the correct answer based upon knowledge and understanding—not memory. Whenever I selected the wrong answer, I re-read and reviewed why the correct answer was correct and why the incorrect answer was incorrect.

The important thing to remember to be successful on the exam is to focus on the key words such as “best,” “most,” “first.” I knew this when I took the exam the first time, but although I felt like I was prepared, I was very nervous and anxious.  I think that negatively affected my performance. I felt completely different when I took the exam for the second time in June 2015. I was not as nervous and anxious. I felt that I was much better prepared, and my score demonstrated that—I scored in the top 20 percent during my second sitting! Now I am looking forward to applying for the CISA certification, as I continue my CISA studies, so I will be a successful Certified Information Systems Auditor.

[ISACA Blog]

Attacks are Effectively Unstoppable

Cyberattacks are effectively unstoppable and people are starting to recognize that. Two things are happening; one is a technical issue and the other is a management issue—both hold promise. Fundamentally we are in detection and remediation cycle. The faster that cycle goes, the better you are. Signature-based detection tools are limited, and anomaly-based tools do not remediate in an automated way so another technical defense is emerging—authenticate transactions using two factor authentication.

The second is implementing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). What we are talking about is agencies being able to accept risk and the whole Federal Information Security Management Act (FISMA) implementation project effectively. Continuous diagnostics and mitigation cracked the idea that information security was just about checklists, but the problem of implementing the RMF is that you uncover flaws in your operational processes. All organizations, even large companies, have a hard time putting discipline into their organizational processes because people are not used to discipline.

Security Issues
Attackers are smart. They study the defenses of an organization so no combination of signature-based, detection-based mechanism and human response can keep them at bay unless it is a security organization. This is a problem for the civilian agencies and commercial organizations since they are not designed to be a security organization. Part of the answer will have to be in the cloud. If the intelligence community establishes a workable cloud model at the high level, it will be propagated to other organizations. Cloud providers can leverage very expensive monitoring, SOC audits and training that agencies cannot afford.

If you assume that code is not securable, then you have to do authenticated transaction underneath the operating system to secure transactions. National Strategy for Trusted Identities in Cyberspace (NSTIC) and FIDO are initiatives by the US government and industry to secure transactions through stronger identity management. The old argument that this would cause a performance hit is irrelevant when modern performance capability grow at Moore’s law speed. In our economy, the way we deal with inferior products is through the plaintiffs’ bar, except for software where there is an exemption. If this is our economic model but we exempt software, how do you expect a change to occur?

Views on US Legislation
Legislatively, the update to FISMA was a useful step forward because it codified the risk management framework in the US federal government. It establishes risk management and risk assessment as a primary function, not merely a response to IG audits. The strategic advantage is that agencies have to do risk management. The other big thing is the whole sharing problem which is the old paradox where those who know will not say and those who say do not know and everyone has a reason to not say what they know. There is a fundamental issue about how businesses avoid liability problems. I do not think the legal model is in place yet to allow business to truly share information with each other to control proprietary knowledge. If you have a product, would you like to admit a vulnerability to a competitor? This is a real issue, but no one has figured out how to manage this yet. Perhaps the US executive order setting up the Information Sharing and Analysis Organizations will meet this need. The US Department of Homeland Security (DHS) Information Sharing and Analysis Organizations (ISAO) model is an attempt to crowd source the security issue. ISAOs will have a common operating environment and culture so they can constitute themselves as information sharing organizations.

Staffing
There are two types of staff. First, there is staff that manages the SOCs. These are the people who are able to read net flow data, understand coding languages and how to detect and remediate an attack, which is a specialized capability. For most organizations, you do not want that capability on your staff due to cost. These people are too highly qualified and specialized; they need to be leveraged across many organizations like the cloud model. Your staff has to be very well educated, but also need to be generalists with business acumen to be able to translate technical information and communicate it to your business owner. Your staff needs to be made up of four parts: incident response, training, certification and authorization, and a security architect. I think if properly filled by people with broad-based experience and credentials with the ability to reach down into the technical staff, then you have a staff that will create a better defense against cyberattacks .

Leo Scanlon
Division Director, IT Security
Office of the Chief Information Officer
US Department of Health and Human Services

[ISACA Blog]

From the Top—Keys to Cyber Risk Management for the Executive

Chances are your organization is either working feverishly to field a cyber risk management program or improve your current program to make it more efficient. The recognition of the importance of risk-based security appears consistent across organizations. A 2013 Ponemon and Tripwire study reported that 81 percent of security and risk professionals in the US said their organizations had a significant or very significant commitment to risk-based security management. Unfortunately, the same study said that only 29 percent of those respondents felt their organization had a formal security risk management strategy that was applied consistently across the enterprise.

There are many challenges with implementing a cyber risk management program. These challenges may differ if the organization is starting a program from scratch, working to incorporate cyber risk into an already established risk program or perhaps working to transition from a compliance-based security program. No matter where your organization sits in this spectrum, there are some key actions that can be taken to strengthen an organization’s risk posture.

Incorporate cyber risk into the organization’s existing risk program
Although many organizations already have an existing risk program, it is not uncommon to find a cyber risk program started and managed external to that structure. Often times this is due to the cyber risk effort evolving from the organization’s cybersecurity program. This does provide the benefit of a great deal of technical expertise but at the detriment of risk and line-of-business expertise. The result is misunderstood or poorly developed risk tolerances that do not align with business objectives and the organization’s inability to properly prioritize risk mitigation actions across the organization.

The key here is to arrive at a structure that has, or at least is based upon, a single, common language, risk tolerance criteria and risk catalog/register. The structure needs to include risk managers, security managers and business unit executives. Organizing the cyber risk program at this higher organizational level and out of IT can also aid in developing a cyber-aware culture in the organization.

Focus on the correct assets
The first major component of any risk methodology is identification. An organization’s specific risk methodology may refer to this step as resource profiling, information system categorization, identification of IT services or something else entirely. The goal, however, is the same—identification of those information assets that must be secured to meet business objectives. If you do not know what is important, not only will you not know what to focus your defenses on, but you will have a harder time justifying a risk assigned to an asset. This discussion should not start with routers and servers, but with the information and services upon which the business depends. Once those are defined, prioritized and agreed upon, then IT can begin cataloging the relevant critical hardware and software. Few organizations have sufficient resources to implement all desired security practices.  Identifying critical assets first focuses your risk program and your scarce resources. Doing this wrong could mean cyber risk ends up being defined in terms of compliance and will impact criticality of the asset at risk.

Expand the use of non-technical controls
On one hand, it only makes sense that technology seems to have become the default answer when protecting information assets. The variety and effectiveness of technical solutions available for consideration have never been greater than they are today. Unfortunately, this focus has come at the cost of neglecting the human layer of our information systems.  Focused, recurring awareness training and exercises, behavior management, and incentivizing desired actions can build an organization’s workforce’s ability to prevent, accurately detect, and quickly react to cyber incidents.

I have only just begun to touch on these considerations for more effective cyber risk management. I will be diving deeper and looking forward to the dialog during my presentation at the CSX North America 2015 Conference. Hope to see you there.

Douglas Rausch, CISSP
President, Aurora CyberSecurity Consultants, Inc.

[ISACA Blog]

ISACA Blog: My Journey to Passing the ISACA CGEIT Exam

While my preparation time for the exam was relatively short, I had been building up experience over the past seven years, which significantly contributed to passing this exam. Being a person who is constantly trying to change my perception regarding the “why” of IT, I came across ISACA and its certifications. Certified in the Governance of Enterprise IT (CGEIT) seemed to be the best fit for my career. Here are a few of the things I learned on my journey to the CGEIT exam.

  • Take time to select the right certification for you:  To achieve this I engaged in some research and brief reading on the various certification tracks, I spoke to persons who were already certified by ISACA and assessed my job critically. By doing this, I was comfortable I had made the right choice of track for me—CGEIT.
  • Become a member:  Signing up for membership provides you discounts and benefits, which are very valuable.
  • Get the official material:  I got the official material as a base to work with, which helps in setting a benchmark to begin the journey to the exam.
  • Assess where you are honestly:  I started off with the practice test first and my results were horrible. At one point I was asking myself, am I crazy to pursue this? But, that is actually what helped me understand that I had a lot of work to do and exactly how much I had to cover.
  • Do some reading:  I read the books and discovered interesting things you sometimes take for granted simply because you may not be consciously aware of its impact. After reading a majority of the material, I redid the practice test and my results were still scary, but I was now in a good position to develop my own personal learning strategy to get me up to exam readiness.
  • Develop a learning strategy:  The same things will not work for everyone, so you have to get creative to design learning habits that work best for you. I ended up breaking down the practice questions and book chapters into smaller groups. I read, engaged questions and before I answered, I linked mentally to my job function/experience so I could see it in proper context. With that, my practice test scores skyrocketed and I could safely narrow down answers to two choices and then analyze further to arrive at the best answer.

Finally, it was time toface the exam.  The exam was well written and even enjoyable.

Now with a successful exam result, what is left to do is to apply for certification, which I am looking forward to doing. Good luck to all aspiring candidates. For even more tips, read my post here: http://bit.ly/1E0Vqce.

Ammett Williams, CCIE
Telecommunication Team leader at First Citizens, TT

[ISACA Blog]

Assessing Security Risks in Third-party Payment Processing

Managing financial information is a dangerous business, and the past year has been marked by a number of significant data breaches. Large companies with the money and power to best protect credit information, such as Target, Home Depot, and Urban Outfitters, have all been affected, leaving smaller companies with less robust security infrastructure feeling like a breach is bound to occur, posing a risk to their customers.

Financial data management does not need to be this stressful. Many of these smaller businesses, however, rely on third-party companies to perform their payment processing and data management, further complicating risk assessment. Here are some issues to consider when dealing with external payment management for your business.

Keeping Networks Separate
One of the greatest problems that data security professionals are encountering today is that networks and servers are increasingly interlinked. These connections make outside infiltration easier than ever, as the links between the private and the public become more numerous. Information thieves are now just a link away from confidential information.

Your payment management company is responsible for making sure that these kinds of connections are minimized, and that those links that do exist are appropriately protected. Ask your third-party provider how they handle network privacy. This includes asking questions about employees’ use of mobile technology in the workplace that could pose a security issue.

Assessing Public Relations
A look at your digital security management company’s public relations (PR) practices could prove very revealing. How does the PR branch of the company talk about security breaches? For many PR offices, any information breach affecting fewer than 10 million people is small. If this kind of minimizing is happening on a regular basis, you may want to turn to a different company to handle your customers’ data.

Categories Are Valuable
Running a business means balancing an array of concerns and connections. So, while you should be extra concerned about the security procedures of any company handling sensitive information, there are other factors to be considered. One system for managing security issues is to rank different companies by risk level. What kind of data are they handling and what is their reputation? Companies with greater risk can be placed under more significant observation and should have their practices audited more frequently.

Reconsider Vulnerability Management
Does your third-party payment manager use an automated vulnerability management system to protect their data? As Gordon Mackay points out, these systems can lull companies into a false sense of security and can be an unwise use of resources. Steer clear of companies using these systems in favor of those that take a more active approach to handling data. Poorly functioning vulnerability management software has been behind a number of breaches, making it far more costly than most realize.

Pay Attention to Staffing
There is a serious shortage of great Internet and data security professionals on the market today. Does the external company doing your payment management employ enough of the best minds out there? And does your third-party company do appropriate background checks on those employees? It is important that you do not just have a single link with a company representative, but rather that you understand the larger atmosphere of the company. Know who is handling your data.

While third-party payment management is often the best solution for small businesses, that does not mean you can take a backseat and leave the whole project up to them. Business owners should always be proactive in their relationships with any company handling sensitive information. Be vigilant about breaches and take responsibility for your data, even when it is not in your hands.

Larry Alton
Freelance writer

[ISACA Now Blog]

English
Exit mobile version